Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-01-2010, 02:12 AM
Starter Member
 
Posts: 2
Default Moving SSH from external IP to internal IP

Hi all.
I just installed ZCS on the CentOS 5.5 machine. It was easy, without any problems and now it is up and running.
The machine which run ZCS is also used as gateway, proxy, firewall and webserver.
Now i want to be more secure because i'm in production, so i decided to move SSH from the public IP, to the internal IP and also on localhost to prevent any possible errors from ZCS. From the moment when i put SSH to run on the port 22 over 127.0.0.1 and 192.168.x.y ip addresses i receive this error:
Quote:
Server error encountered
Message: system failure: exception during auth {RemoteManager: mail.mastersystem.ro->zimbra@mail.mastersystem.ro:22} Error code: service.FAILURE Method: GetMailQueueInfoRequest Details:soap:Receiver
When i put it again on the public ip, everything works fain.
So i'm asking, if the SSH can be run only on the ip address which correspond to the MX registration or can be changed to any ip address from machine?
And.. how can i make this whithout getting an error?
I followed the procedure described here Mail Queue Monitoring - Zimbra :: Wiki but whithout any results.
Question: Can i move SSH on lan interface and how can i do that?

Thank you.
Reply With Quote
  #2 (permalink)  
Old 06-01-2010, 02:52 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by Snakebite View Post
Hi all.
I just installed ZCS on the CentOS 5.5 machine. It was easy, without any problems and now it is up and running.
The machine which run ZCS is also used as gateway, proxy, firewall and webserver.
You should not be running your Zimbra server on the Gateway/Firewall/Proxy/websererver for you LAN - you will end-up with problem.

Quote:
Originally Posted by Snakebite View Post
Now i want to be more secure because i'm in production,
See comment above.

Quote:
Originally Posted by Snakebite View Post
so i decided to move SSH from the public IP, to the internal IP and also on localhost to prevent any possible errors from ZCS. From the moment when i put SSH to run on the port 22 over 127.0.0.1 and 192.168.x.y ip addresses i receive this error:

When i put it again on the public ip, everything works fain.
So i'm asking, if the SSH can be run only on the ip address which correspond to the MX registration or can be changed to any ip address from machine?
And.. how can i make this whithout getting an error?
I followed the procedure described here Mail Queue Monitoring - Zimbra :: Wiki but whithout any results.
Question: Can i move SSH on lan interface and how can i do that?
The only thing you should do in these circumstances is block ssh at the firewall. If you wish to change ssh to a different port then search the forums for details. I'd strongly advise you to move the Zimbra server to another box inside your LAN.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.